linux/security
Linus Torvalds 231e9d447e selinux/stable-7.2 PR 20260615
-----BEGIN PGP SIGNATURE-----
 
 iQJIBAABCgAyFiEES0KozwfymdVUl37v6iDy2pc3iXMFAmowS9AUHHBhdWxAcGF1
 bC1tb29yZS5jb20ACgkQ6iDy2pc3iXMzdBAAxsJDUmULW7fJu595G36fAkshrR01
 6/1bWluSk6rHVg8S951I0rQlwIRZN+0fj6m7jT4ZsbLeOC34nVPDRVJS+ZkXkl+B
 qe+fjWhymLcTgSRciyWXSGEoXqbE4gsZwf8cL2v+oLhy8+pMqASYVnru2/07/f+H
 vZ+l2tvGzgoOKYidC261pCpfUaLWwklAc4JLBhoMQM0GvuH9n2fzcoBkyNdtjj/f
 /SDFZ9fKPaQ7GooUarQHuf6TjeI/S/0kFmNn+8qTPxP3eEeBMoY1JrDFti57NK5H
 En6NioQEm8ODDC7PxxrDfAP3B7SHK6AYzH2i7GROD7O0BbUTlrXvL0L3v/izstfu
 zmDUlStyib7FIEo7g7e4ZJnHK+U7MOsSFcVNutfW4volSritE20rHDya+pK4TaFF
 vLWOJJxgBlLLhORJWeJ8SO0BvZHu7oFahQ4YG3s80BvmYSRhojuRf3pWfwXB6CFM
 glUCLz15n4CSTMym4zil/UdoY6Iu31Cw1T5jHBaT3/FNSk3w3baYeR5kr2dXsVXR
 N9DCRAZ37Sp0foiyFkDRaucNSPVcgLtGWorHiYyyihpV0at+9Ye+7KCskU8Ej0HT
 u60tBaKts5o+378yCQagcci3Sh5CwppeNhezBhW8M8C9uJt4dFP7W+iNlX1+E7Px
 7LuRNHi9IO5yhDM=
 =m15j
 -----END PGP SIGNATURE-----

Merge tag 'selinux-pr-20260615' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux

Pull selinux updates from Paul Moore:
 "A number of SELinux patches, almost all of which are either minor
  fixes or hardening patches:

   - Additional verifications when loading new SELinux policy

     Multiple patches by Christian Göttsche to add additional
     validations to the code responsible for loading and parsing SELinux
     policy as it is loaded into the kernel.

   - Avoid nontransitive comparisons comparisons in our sorting code

     Done to prevent unexpected sorting results due to overflow. Qualys
     documented a similar issue with glibc

	https://www.qualys.com/2024/01/30/qsort.txt

   - Consistently use u16 for SELinux security classes

   - Move from page allocations to kmalloc() based allocations

     Unfortunately one of these patches had to be reverted, but you
     should see a fixed version during the next merge window.

   - Move from kmalloc_objs() to kzalloc_objs() in the policy load code

   - Reorder sel_kill_sb() slightly to match other pseudo filesystems

   - Simplify things with QSTR() instead of QSTR_INIT()

   - Minor comment typo fixes"

* tag 'selinux-pr-20260615' of git://git.kernel.org/pub/scm/linux/kernel/git/pcmoore/selinux:
  selinux: revert use of __getname() in selinux_genfs_get_sid()
  selinux: comment spelling fix in ibpkey.c
  selinux: comment typo fix in selinuxfs.c
  selinux: hooks: use __getname() to allocate path buffer
  selinux: use k[mz]alloc() to allocate temporary buffers
  selinux: check for simple types
  selinux: more strict bounds check
  selinux: beef up isvalid checks
  selinux: reorder policydb_index()
  selinux: check type attr map overflows
  selinux: check length fields in policies
  selinux: more strict policy parsing
  selinux: use u16 for security classes
  selinux: avoid nontransitive comparison
  selinux: switch two allocations to use kzalloc_objs()
  selinux: fix sel_kill_sb()
  selinux: use QSTR() instead of QSTR_INIT() in init_sel_fs
2026-06-17 12:41:00 +01:00
..
apparmor + Cleanups 2026-04-24 09:22:21 -07:00
bpf lsm: replace the name field with a pointer to the lsm_id struct 2025-10-22 19:24:18 -04:00
integrity integrity-v7.1 2026-04-17 15:42:01 -07:00
ipe treewide: change inode->i_ino from unsigned long to u64 2026-03-06 14:31:28 +01:00
keys security/keys: fix missed RCU read section on lookup 2026-05-28 11:45:41 -07:00
landlock fs: add icount_read_once() and stop open-coding ->i_count loads 2026-05-11 23:12:28 +02:00
loadpin Convert 'alloc_flex' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
lockdown lockdown: move initcalls to the LSM framework 2025-10-22 19:24:27 -04:00
safesetid Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
selinux selinux/stable-7.2 PR 20260615 2026-06-17 12:41:00 +01:00
smack security,fs,nfs,net: update security_inode_listsecurity() interface 2026-05-01 11:29:33 -04:00
tomoyo tomoyo: use u64 for holding inode->i_ino value 2026-04-15 00:00:10 +09:00
yama Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
commoncap_test.c security: Add KUnit tests for kuid_root_in_ns and vfsuid_root_in_currentns 2026-01-09 11:28:28 -06:00
commoncap.c security: Add KUnit tests for kuid_root_in_ns and vfsuid_root_in_currentns 2026-01-09 11:28:28 -06:00
device_cgroup.c Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
inode.c securityfs: use kstrdup_const() to manage symlink targets 2026-03-17 17:13:36 -04:00
Kconfig proc: make PROC_MEM_FORCE_PTRACE the Kconfig default 2026-04-13 09:12:37 -07:00
Kconfig.hardening security/Kconfig.hardening: Remove tautological condition from CC_HAS_RANDSTRUCT 2026-05-27 15:20:04 -07:00
lsm_audit.c treewide: change inode->i_ino from unsigned long to u64 2026-03-06 14:31:28 +01:00
lsm_init.c lsm: add backing_file LSM hooks 2026-04-03 16:53:50 -04:00
lsm_notifier.c lsm: split the notifier code out into lsm_notifier.c 2025-10-22 19:24:15 -04:00
lsm_syscalls.c lsm: hold cred_guard_mutex for lsm_set_self_attr() 2026-05-14 16:47:59 -04:00
lsm.h lsm: add backing_file LSM hooks 2026-04-03 16:53:50 -04:00
Makefile lsm: split the init code out into lsm_init.c 2025-10-22 19:24:16 -04:00
min_addr.c lsm: preserve /proc/sys/vm/mmap_min_addr when !CONFIG_SECURITY 2026-01-29 13:56:53 -05:00
security.c security,fs,nfs,net: update security_inode_listsecurity() interface 2026-05-01 11:29:33 -04:00